CVE-2026-85709Medium· 5.3▾ TwilightPoC availableLightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and l…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and lightrag_server.py. The detail=str(e), detail=str(exc), and equivalent formatted-message paths expose server filesystem paths, database host, port, user, and database names, language-model provider diagnostics, configuration details, and Python library internals to a network client that can trigger an error. The default unauthenticated configuration makes those responses reachable without credentials, and URI-configured backends can disclose connection strings containing credentials depending on the underlying driver error. This issue is fixed in version 1.5.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
lightrag-hku <= 1.5.4Patched in:
lightrag-hku 1.5.5Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86062Medium· 6.1LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-85725Medium· 5.9LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-85740High· 7.1LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-85734Critical· 9.1LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-92576High· 8.6HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses
CVE-2026-90808Medium· 6.3A vulnerability was determined in HKUDS nanobot up to 0.2.1